21 - FTP
Banner Grabbing
Telnet
Netcat
NSE Script
FTP
FTP Exploitation
Anonymous Login
Note: During the port scanning phase Nmap’s script scan (-sC
), can be enabled to check for FTP Bounce and Anonymous Login.
Try anonymous login using anonymous:anonymous
credentials.
List all files in order.
FTP Browser Client
Due to its insecure nature, FTP support is being dropped by Firefox and Google Chrome.
Try accessing ftp://user:pass@10.0.0.3
from your browser. If not credentials provided anonymous:anonymous
is assumed.
Brute Forcing
SecLists includes a handy list of FTP default credentials.
Configuration files
It is important to examine these config files:
Other
Binary and ASCII
Binary and ASCII files have to be uploading using the binary
or ascii
mode respectively, otherwise, the file will become corrupted. Use the corresponding command to switch between modes.
Download all files from FTP
Last updated